A high-severity flaw tracked as CVE-2026-15416 allows unauthenticated remote code execution in Argo CD by abusing the repo-server's GenerateManifest gRPC endpoint. According to Red Hat and related disclosures, an attacker with network access to the repo-server interface can exploit malicious KustomizeOptions, including BuildOptions or BinaryPath, to run arbitrary commands inside the repo-server pod. The issue is rated CVSS 8.9 and mapped to CWE-306 for missing authentication on a critical function.
The vulnerability can also be chained with access to the Argo CD Redis cache to tamper with cached data and push attacker-controlled Kubernetes manifests to Argo CD-managed environments, creating a path to full cluster compromise. Red Hat said affected products include Argo CD deployments and related OpenShift components, while OpenShift GitOps 1.20 and 1.21 are not affected because default Kubernetes NetworkPolicy settings block the required access to internal repo-server and Redis services. Recommended actions include patching to a fixed version, preventing external exposure of the repo-server, restricting network access to the gRPC endpoint and Redis, and reviewing deployment configurations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-15416 was published as a high-severity Argo CD vulnerability with CVSS 8.9 and CWE-306 classification. The publication described unauthenticated remote code execution through the repo-server's GenerateManifest gRPC endpoint and identified affected Red Hat products and patching guidance.
A Red Hat Bugzilla entry documented technical details of the vulnerability, explaining that malicious KustomizeOptions such as BuildOptions or BinaryPath could be abused to execute arbitrary commands in the repo-server pod. It also described how combining the flaw with Redis cache manipulation could enable deployment of attacker-controlled Kubernetes manifests.
Red Hat published an advisory for CVE-2026-15416 describing an unauthenticated remote code execution flaw in Argo CD's repo-server via the GenerateManifest gRPC endpoint. The advisory also noted potential cluster compromise through Redis cache manipulation and listed mitigations such as restricting network access and updating to a fixed version when available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.